August 2018 Request Professional Edition Admin Summary
Initial Post
Request
Support for Plain Text FTP to End on 1 September, 2018SAP Concur announced the End of Support for plain text FTP to transfer data to and from SAP Concur.
Plain text FTP is not a secured protocol and has inherent security vulnerabilities. On 1 September, 2018, SAP Concur Operations will apply a security update to our File Transfer infrastructure, restricting the use of plain text FTP as a part of our ongoing commitment to securing our customers’ data and meeting the audited security requirements of the SAP Concur Trust Platform.
For more information, refer to the Plain Text FTP Retirement FAQ (English Only).
What This Means – The Client Experience: After 1 September, 2018, uploads of file types such as Employee, List, Attendee and other Import files, as well as downloads of SAE and other Extract files that use Plain Text FTP, will not be accepted via SAP Concur’s Filemover system. This will significantly impact client usage of SAP Concur products such as Concur Travel, Concur Expense and Concur Invoice, as well as integration activities to customers’ financial systems. There will be no exceptions beyond 1 September, 2018.
SAP Concur Platform
Callout Server Requirements UpdateSAP Concur is upgrading the servers that support the SAP Concur Platform Callouts. This maintenance includes the Production Proxy Migration and PWS Server Migration to VM.
The North American Data Centre update has been completed. The EMEA Data Centre PWS Server Migration to VM is completed, and the Production Proxy Migration is estimated to be completed on 31 October, 2018.
These servers support the following functionality:
Fetch Attendee Data Callout
Fetch List Item Callout
Event Notification Callout
Launch External URL Callout
Concur Salesforce Connector
Be aware that this maintenance means that for any customer callout URLs, SAP Concur has the following requirements:
The endpoint is secured with SSL/TLS.
The endpoint uses a minimum of TLS 1.0, but TLS 1.2 is preferred.
The endpoint must employ Diffie-Hellman cipher suites with key sizes >1024 bits.
Due to the ever-evolving world of SSL and standards, we do not publish a specific list of permitted cipher suites, but we generally advise that a modern industry supported list is utilised.
The endpoint must present an SSL certificate with a chain to a valid root that can be verified. If the chain cannot be verified without installing additional certificates, the calls from SAP Concur will fail.
Business Purpose / Client Benefit: This maintenance will mitigate the out-of-warranty issue with our current hardware.
Planned Changes
The items in this section are targeted for future releases. Concur reserves the right to postpone implementation of – or completely remove – any enhancement/change mentioned here.
**Planned Changes** Personalised Concur OpenConcur Open is the SAP Concur service status dashboard, which displays known and widespread outages and incidents for select SAP Concur services and all data centres. Concur Open displays the current service status as well as incident history for the past 20 days.
In a future release, there will be new functionality added to Concur Open. Users can continue to access Concur Open and view Concur service availability; no functionality will be removed. However, with the release, SAP Concur users will be able to log in to Concur Open and:
- View service status for the services and the data centre that are specific to their company
- Access subscription options for updates about the incidents that affect the services specific to their company
- View service history for the past two years as well as detailed root cause analysis information and the actions taken by SAP Concur for specific incidents
Business Purpose / Client Benefit: Customers use Concur Open to monitor their SAP Concur services outages, status and availability. Adding this new functionality will provide customers with a personalised view of their service status and availability. SAP Concur's goal is to provide a more accurate and transparent view of incidents/outages.
Client Notifications
SAP Concur Non-Affiliated SubprocessorsThe list of non-affiliated subprocessors is available here: SAP Concur list of Subprocessors (English Only)
Monthly Browser CertificationsMonthly browser certifications, both current and planned, are available with the other SAP Concur monthly release notes, accessible from What's New - Professional Edition
